IP Library Granted Patent US 10,880,097
Granted Patent B2
US 10,880,097 · App. 16/162,776 · Granted Dec 29, 2020

Flexible provisioning of attestation keys in secure enclaves

Inventors: Vincent R. Scarlata (Beaverton, OR); Francis X. McKeen (Portland, OR); Carlos V. Rozas (Portland, OR); Simon P. Johnson (Beaverton, OR); Bo Zhang (Raleigh, NC); James D. Beaney, Jr. (Raleigh, NC); Piotr Zmijewski (Kartuzy, PL); Wesley H. Smith (Raleigh, NC); Eduardo Cabre (Chandler, AZ)
Assignee: Intel Corporation
H04L9/3252G06F21/44G06F21/53G09C1/00H04L9/0866H04L9/14H04L9/302H04L9/3066H04L9/3234H04L9/3247H04L9/3249H04L63/06H04L63/062H04L63/0823H04L63/12H04L2209/127
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,880,097
App. No.
16/162,776
Granted
Dec 29, 2020
Kind
B2
Abstract

A computing platform implements one or more secure enclaves including a first provisioning enclave to interface with a first provisioning service to obtain a first attestation key from the first provisioning service, a second provisioning enclave to interface with a different, second provisioning service to obtain a second attestation key from the second provisioning service, and a provisioning certification enclave to sign first data from the first provisioning enclave and second data from the second provisioning enclave using a hardware-based provisioning attestation key. The signed first data is used by the first provisioning enclave to authenticate to the first provisioning service to obtain the first attestation key and the signed second data is used by the second provisioning enclave to authenticate to the second provisioning service to obtain the second attestation key.

Claims (14)

1. One or more non-transitory computer-readable media having instructions stored thereon that, upon execution of the instructions by one or more processors of a computing device, are to cause the computing device to:

instantiate a first logical component on a computing device;

identify a first request from a second logical component, wherein the first request is related to use of the hardware-based key to sign first data based on the hardware-based key, wherein the first logical component is to maintain the hardware-based key;

sign, by the first logical component, the first data based on the hardware-based key; and

return the signed first data to the second logical component, wherein the signed first data is to authenticate the second logical component to a first service in association with generation of a second key that is to attest characteristics of a first application on the computing-device.

2. The one or more non-transitory computer-readable media of claim 1 , wherein the hardware-based key is based on a root key persistently stored on the computing device.

3. The one or more non-transitory computer-readable media of claim 1 , wherein the hardware-based key is derived from fuses set in the computing-device.

4. The one or more non-transitory computer-readable media of claim 1 , wherein the instructions are further to:

identify a second request from a third logical component implemented on the computing-device, wherein the second request is related to use of the hardware-based key to sign second data;

sign, by the first logical component, the second data based on the hardware-based key; and

return the signed second data to the third logical component, wherein the signed second data is to authenticate the third logical component to a second service in association with generation of a third key that is to attest characteristics of a second application on the computing-device.

5. The one or more non-transitory computer-readable media of claim 4 , wherein the hardware-based key corresponds to a certificate held by both the first and second services.

6. The one or more non-transitory computer-readable media of claim 4 , wherein the second key is a cryptographic key of a first type and the third key is a cryptographic key of a different, second type.

7. The one or more non-transitory computer-readable media of claim 6 , wherein the second key is an Enhanced Privacy Identifier (EPID) key and the third key comprises an Elliptic Curve Digital Signature Algorithm (ECDSA) key or a Rivest-Shamir-Adleman (RSA) key.

Continuity (3)
Continuation 15279527 · Sep 29, 2016
Provisional Application 62345325 · Jun 3, 2016
Related Publication 20190052469A1 · Feb 14, 2019
Cited By (1)
US 12,362,938